CVE-2025-54236
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to take over a user's session without needing any interaction from them, which can lead to unauthorized access to sensitive information. It affects several versions of Adobe Commerce, so if you're using one of those versions, it's critical to update immediately to prevent exploitation.
Technical Description
Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an Improper Input Validation vulnerability. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue does not require user interaction.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Sep 9, 2025
7 months ago
Last Modified
Mar 16, 2026
23 days ago
Vendor
adobe
Product
commerce